In short
  • The questionnaire is not really about AI. It is about who answers when the AI is wrong, and the buyer is asking because it now has that question itself.
  • Four answers create liability you did not previously have: that you are compliant, that you are certified, that you do not use AI, and that your vendor covers it. Each is easy to write and hard to stand behind.
  • Three documents answer most of any questionnaire: a list of the AI tools you use and what each touches, a one page description per tool of what it does and where a human checks it, and your vendor terms.
  • Not yet is an acceptable answer when it carries a date and an owner. Confident and wrong is not, and it is the answer that follows you.
  • What you write becomes a contractual representation, and often an insurance proposal answer. Both are worth re-reading before you send the spreadsheet back.

Why the questionnaire arrived

Three things happened at roughly the same time, and your client is feeling all of them.

The first is that buyers who deploy AI have obligations of their own. Where a business deploys a high-risk AI system, Article 26 of the EU AI Act requires it to take appropriate technical and organisational measures to ensure the system is used in accordance with the instructions for use accompanying it, to assign human oversight to people with the necessary competence, training and authority, and, where it controls the input data, to ensure that data is relevant and sufficiently representative in view of the intended purpose. A buyer cannot do any of that about your tool without knowing what your tool is. The questionnaire is how it finds out.1

The second is 9 December 2026. From that date the revised Product Liability Directive applies to products placed on the market or put into service after it, and it treats software as a product. That moves a set of questions about who answers for a defect from the theoretical to the contractual, and procurement teams have noticed. What it does and does not cover is set out in our guide to the new product liability law for small businesses.2

The third is simply that your client is being asked the same questions by its own customers and its own insurers, and is passing them down. That is worth knowing, because it tells you what a good answer looks like. Your client needs something it can forward.

What the buyer is actually trying to establish

Behind thirty questions there are usually three.

What does the AI do in the thing we are buying? Not which model. What decisions or outputs it produces, and what part of the service depends on it.

Who answers if it is wrong? You, the buyer, or a vendor two steps back, and with what behind that answer.

Can you show us anything? Meaning: is there a record, or is there confidence.

An answer set that addresses those three plainly will satisfy most questionnaires, including questions it does not literally answer, because the person reading it can see the shape of the business behind it.

The eight questions that keep appearing

1. Do you use AI in delivering services to us? Answer per service line, not for the company. Most businesses have three or four uses and one of them is invisible to management because it sits inside a tool somebody bought on a card. Name the tools and what each touches. This question is where an inventory earns its keep.

2. Is your system high-risk under the EU AI Act? Careful. High-risk is a defined classification with its own rules, and most business software is not in one of the listed categories. The safe answer states what the tool does and which category you believe it falls in or outside, rather than asserting a bare conclusion. If your client is the one deploying something into a high-risk area, its classification question is not yours to answer.

3. Are you certified? Only say yes if you hold something, and then say what it covers and when it was issued. A certificate is a statement about a defined scope on a defined date. Describing it loosely is where this question turns into a problem later, which is the subject of what it means when a vendor says it is certified.

4. Which models or vendors do you use? Answer factually and keep it current, because it is the answer most likely to go stale. If you change vendor after the contract is signed and the answer is in the contract, you may have just created a notification obligation you did not read.

5. What human oversight is there? The best answer is boring and specific: who reviews what, at which point, and what they are able to do about it. The weakest answer is a policy statement. Oversight that exists only in a policy is discovered quickly by anyone who asks a second question.

6. What do you log, and for how long? Say what you actually retain rather than what would be ideal. Retention that was chosen by a vendor default is not a decision your business has made, and a buyer can usually tell the difference. Our guide on documenting AI decisions sets out a workable minimum.

7. Do you carry insurance that responds to AI errors? This is not the same question as whether you hold professional indemnity or cyber cover. Answer it by reference to what you hold, and do not characterise what a policy would pay for unless you know. If you have not asked the question of whoever arranges your cover, ask before you answer it in writing. What to tell your broker about AI agents covers that conversation.

8. Will you indemnify us for AI-related losses? A commercial question wearing a compliance question's clothes. It belongs with whoever signs your contracts, and the answer interacts with what your cover would actually respond to. An indemnity you give freely is not automatically an indemnity your insurance supports.

The four answers that create liability you did not have

"We are EU AI Act compliant." Compliant with which obligation, for which system, as of when. A bare compliance statement covers everything, which makes it the easiest statement in the document to disprove. Replace it with specifics and you are both more credible and better protected.

"Our AI is certified." If it is, say by whom, against what, on what date, and what the scope excluded. If a vendor's certificate is doing the work, attach the vendor's certificate and say it is theirs.

"We do not use AI." This is often written in good faith and is often wrong, because AI features arrived inside tools that were bought for other reasons. It is also the answer that ages worst, because the first person to notice the AI feature in your stack will be the person who received this answer.

"Our vendor is responsible for that." Perhaps, between you and the vendor, and subject to what the contract says. It says nothing about your position with your client, who contracted with you. Read the vendor terms before you rely on them in writing, using the vendor contract review guide.

The three documents that cover most of it

The list. Every AI tool in the business, what it is used for, which clients or processes it touches, who owns it internally, and the date the list was last checked. Half a day to build the first time. It answers questions 1, 4 and 6 directly and makes every other answer faster.

The one pager per tool. What the tool does, what it produces, where a human reviews the output, what happens when the human disagrees, and what you tell customers about it. One page each. This is the document a buyer will actually read, and it is the one that makes your answers consistent across three different questionnaires from three different clients.

The vendor terms. The current version, not the one you signed three years ago, with the liability and indemnity sections marked. You cannot answer question 8 honestly without them.

Everything else is assembled from those three. If you build them once, the next questionnaire is an afternoon instead of a fortnight, and the answers do not contradict the ones you sent last quarter.

How to write the honest version of not yet

Most questionnaires have four or five questions where the true answer is that you have not done it. The instinct is to answer around them. The better move is a short standard form: what is true today, what is not, who owns it, and by when.

"We do not currently retain model outputs beyond the vendor's default period. We have identified this and are setting a retention period by the end of Q4 2026. Owner: operations manager."

That answer loses very few deals. It reads as a business that knows its own state. The alternative, a confident yes that unravels during onboarding, costs the deal and the relationship, and it is on record.

What your answers become afterwards

This is the part worth pausing on before you hit send.

Your answers frequently end up annexed to the contract, and an answer in a contract is a representation. Some of them get repeated into an insurance proposal, where the accuracy of what you state matters to the cover in ways that depend entirely on the wording and on the law of your country, which this desk has not read for your case. And if a dispute ever reaches a court about a product placed on the market after 9 December 2026, the Product Liability Directive allows a national court to order a defendant to disclose relevant evidence at its disposal where a claimant has presented facts and evidence sufficient to support the plausibility of the claim, and it presumes the product defective where the defendant fails to disclose.3

None of that is a reason to answer sparsely. It is a reason to answer accurately, and to keep a copy of what you sent, with the date, next to the version of the system it described. The same file that satisfies a buyer today is the file that answers an underwriter next year and a lawyer the year after. The assessor's version of that standard is set out at agentcertified.eu, and the insurance reading of it at agentinsured.eu.

One clause to check before you sign

When the questionnaire turns into a contract, look for the clause that says you will notify the client of material changes to your use of AI. It is increasingly common, it is reasonable, and it is the clause most often breached by accident, because changing a vendor or switching on a new feature does not feel like a contractual event. Decide who inside your business owns that notification before you agree to it. If nobody owns it, it will not happen.

Questions

Why is a client asking us to fill in an AI questionnaire?

Usually for three reasons at once. The client has duties of its own if it deploys a high-risk AI system, including using it in accordance with the instructions for use and assigning human oversight under Article 26 of Regulation (EU) 2024/1689. It wants to know who answers if something goes wrong, because from 9 December 2026 the revised Product Liability Directive treats software as a product. And its own customers and insurers are asking it the same questions, so it is passing them down the chain.

Should we say we are EU AI Act compliant?

Only if you can say exactly what you mean by it, and most businesses cannot. Compliant with what, as of when, for which system. A bare statement of compliance is a representation that can end up in a contract, in an insurance proposal and in a dispute, and it is one of the easiest statements to disprove because it covers everything. A specific answer is both more useful to the client and safer for you.

What if the honest answer to a question is that we do not know?

Write that, with a date and a next step. Buyers are used to gaps and are rarely surprised by them. What damages a relationship, and creates a real problem later, is an answer that was confident and wrong. A gap with an owner and a date reads as a business that knows what it does not know.

Does saying our vendor is certified protect us?

No. A certificate belongs to whoever was assessed, covers whatever was in the scope of that assessment, and was true on the date it was issued. It does not transfer to you, it does not describe how you configured the tool, and it is not a defence. If a vendor's certification matters to your answer, record what was certified, by whom, when and what the scope excluded, and attach the certificate rather than describing it.

Do we have to tell clients we use AI in their work?

The AI Act sets specific transparency duties rather than a general one. Article 50 covers systems that interact directly with people, machine-readable marking of synthetic content by providers, notice where emotion recognition or biometric categorisation is used, and disclosure of deep fake content and of AI-generated text published to inform the public on matters of public interest, each with its own exceptions. Separate duties can arise from your contract, your professional rules and consumer law, and those are treated in our guide on whether clients have a right to know.

How long does building the three documents take?

For a business with three or four AI tools, about a day for the first version: half a day for the list and a couple of hours per one pager, plus the time to retrieve current vendor terms. The second questionnaire then takes an afternoon. The saving is real, but the more important effect is that your answers stop contradicting each other across clients.

Sources

  1. Regulation (EU) 2024/1689 (EU AI Act), Article 26 (obligations of deployers of high-risk AI systems), including the duties on instructions for use, human oversight and input data, read at the European Commission AI Act Service Desk, ai-act-service-desk.ec.europa.eu, on 25 September 2026. Following Regulation (EU) 2026/1744 the obligations for stand alone Annex III high-risk systems apply from 2 December 2027 and those for Annex I systems from 2 August 2028.
  2. Directive (EU) 2024/2853 on liability for defective products, Article 2(1) (application to products placed on the market or put into service after 9 December 2026) and Article 4(1) with recital 13 (software, including AI systems, as a product), read in the Official Journal text served by the Publications Office of the European Union at publications.europa.eu.
  3. Directive (EU) 2024/2853, Article 9(1) (disclosure of evidence on a plausible claim) and Article 10(2)(a) (presumption of defectiveness on failure to disclose), read in the same text.
  4. Regulation (EU) 2024/1689, Article 50 (transparency obligations), read at ai-act-service-desk.ec.europa.eu on 25 September 2026. That page carried a notice stating that the provision has been amended by the Digital Omnibus on AI and that the displayed text had not yet been updated; no amended text was read for this article.
  5. The eight recurring questions, the four risky answers, the three documents and the not yet form are this desk's own practical guidance. They are not requirements of any law, standard or framework, and they are not attributed to any authority, certification body or insurer.
  6. This article does not describe the national law of any Member State, the terms of any insurance policy, or the rules of any professional body. No policy wording was read for it.
  7. No relationship exists between Future Proof Intelligence and any authority, institution or company named in this article.